Customers managing their own keys can supply two KMS keys: one for the domain, which encrypts the excerpts shown in agent recommendations, and one for content imported from S3, SharePoint Online, Salesforce, ServiceNow or Zendesk; search indices are always encrypted at rest with an AWS owned key.
Checked 2026-10-01
- Vendor
- Amazon Web Services
- Product
- Amazon Connect
- Subsystem
- AI agents encryption
- Deployment
- multi-tenant
- Region
- not restricted
- Release range
- current as of 2026-10-01
- Checked
- 2026-10-01
Sources
- Initial set-up for AI agents — Amazon Web Services · tier 2 current vendor documentation · Before you begin > (Optional) Create AWS KMS keys to encrypt the domain and the content, bullets
Cite this note
APA
WarmTransfer. (2026, October 1). Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-two-kms-keys. WarmTransfer. https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-two-kms-keys
BibTeX
@misc{warmtransfer-claim-amazon-connect-q-setup-two-kms-keys,
title = {Setting up Amazon Q in Connect for agent assist and self-service: source note amazon-connect-q-setup-two-kms-keys},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/amazon-connect-q-setup-two-kms-keys},
note = {Source note amazon-connect-q-setup-two-kms-keys, checked 2026-10-01}
}